RiskMandate Design Studio
Writes storyboards, draws them with image models, proposes cast, and delivers into its own folders of the private vault.
Writes storyboards, draws them with image models, proposes cast, and delivers into its own folders of the private vault.
Turns a story into a storyboard in the site's shape, draws it with whichever image model is being tried, keeps the original of every picture and a register of what drew it and when, proposes new cast to the lead, and answers requests from the publisher by message. It works in its own folders and never touches what is published.
Reads at the start of every session, in this order
README.mdin the vault: what the vault is and whose folders are whosemail/README.mdin the vault: the one rule, the message shape, the check-inmail/sessions/studio.chatgpt/brief.mdin the vault: its role and what it does on a check-inpublished/cast.jsonthe cast as published, with what each stands formail/mailroom/studio.chatgpt/what is being asked of itSkills
Tools: conversation and uploads · browsing (the vendor's egress) · code execution (the vendor's sandbox) · image generation. Reach: host is the vendor's environment and sandbox; not the lead's machine; tenant is the stories vault at the vault host, with the account token in its conversation; world is the vendor's egress: any page it is asked to read.
The catalogue's template for this shape is derived from the model site's web tree, with browsing off, and has one row. This deployment has more: the rows below are what this agent was observed to do on 26 September 2026, when it created and pushed the stories vault, read from the vault it left behind and from its own decision record. Each row: the primitive, what stands in the way, how we know, and what was done or read. A barrier is a control only in the fourth case.
authenticate-as.credential.tenantAct in accounts with the credentials it holds · no undo · organisation● nonenothing in the wayobservedvia code execution: sgit --tokenThe vault host's access token, pasted by the lead into the conversation; it pushed with it. The token is the account's, not one vault's, and it now sits in a conversation the vendor retains under its own terms.read.credential.hostRead credentials stored where it runs · no undo · organisation● nonenothing in the wayobservedvia conversation; code executionThe token and the vault key are in its conversation and, for the session, in its sandbox. Its own guidance says to keep credentials outside the content tree, and its file manifest shows none inside; that is a rule it wrote for itself.send.endpoint.worldReach any host on the internet · no undo · mixed◐ settinga switch the account can flipobservedvia browsing; code executionIt read pages on riskmandate.ai and sgit.ai (its sources/README.md lists them, read 26 September) and it reached the vault host to push. The egress is the vendor's. Control: The account's tool settings at the vendor: browsing and code execution are toggles the lead can turn off. A setting, at the vendor, not a boundary of ours.write.repository.tenantPush to a code host (any branch it can reach) · undo with effort · organisation● nonenothing in the wayobservedvia code execution: sgit create, sgit pushIt created the stories vault dy4u2m9c and pushed 153 files (commit bdf599541e53, 26 September). Any path in the vault; the single-writer rule that keeps it to its own folders is prose in mail/README.md.execute.process.selfRun programs inside its own sandbox only · undo · own◐ settinga switch the account can flipobservedvia code executionIn its sandbox it ran sgit and computed a SHA-256 for each of 153 files (file-manifest.json in the vault). Control: The same toggle.grant.credential.selfChange its own permission settings · undo · organisation● nonenothing in the wayobservedvia code execution: sgit createsgit create minted the vault key and printed it into the conversation for the lead. With the account token it can mint more.read.file.projectRead the project it is working on · undo · organisation● nonenothing in the wayobservedvia conversation and uploadsWhat the lead pastes or uploads, and what it fetched: it holds snapshots of brand.md and the merch brief from this site under sources/raw/. A record once read is on the vendor's side.Not in the grant, and why
send.message.world: No mail. A message in the vault is a file.write.repository.project: It has no repository attached; the site's repository is not reachable with anything it holds.create.record.world: Nothing it holds publishes under a name; what it draws reaches the public only through the publisher.Not in the grammar: Generating an image. Keeping a conversation on the vendor's side, with what was pasted into it. Both are real and neither is one of the 23.
Authored 26 September 2026 by the lead, in the sessions of 26 September, written down by the publisher; the first draft to argue with.
Wanted (5)
read.file.projectsend.endpoint.worldexecute.process.selfauthenticate-as.credential.tenantwrite.repository.tenantRefused (2)
grant.credential.selfread.credential.hostUnstated (0)
nonewrite.repository.tenant: wanted, with instances: its own folders (artwork/, stories/, cast/, prompts/, decisions/, sources/, guidance/, versions/, archive/, _page.json, mail/studio.chatgpt/) and the mailrooms. Never published/, board/ or another party's folder. The instances are prose; the grant does not know them.send.endpoint.world: wanted for two things: reading this site's public pages, and pushing the vault. Nothing else is asked for.authenticate-as.credential.tenant: wanted for the one vault. The token it holds reaches every vault the account has, which is more than the mandate.grant.credential.self: refused: no new vaults, no new keys, after the one it made.read.credential.host: refused beyond the one token and the one key it was handed; never into a file it pushes.Excess is what the grant has and the mandate did not ask for; unbounded excess is the part of it with nothing in the way but a switch or a sentence. That number is the only one a control can move, and section 06 says which control would move it.
Excess, refused by the mandate (2)
grant.credential.selfread.credential.hostExcess, unstated (0)
noneUnbounded excess (2)
grant.credential.selfread.credential.hostShortfall (0)
noneAligned (5)
read.file.projectsend.endpoint.worldexecute.process.selfauthenticate-as.credential.tenantwrite.repository.tenantChecks
Never
This provision requires X; the grant does not bound X; a control of type Y at layer Z would bound X. Each line moves rows from the unbounded count.
authenticate-as.credential.tenant, write.repository.tenant, grant.credential.selfa write token scoped to one vault, or a vault of its own that only it writes and the publisher pulls fromthe vault hostthe account token reaches every vault the account holds; the mandate wants oneread.credential.hosta token handed to the sandbox for one run rather than pasted into a retained conversationthe vendor's platforma conversation is a record; a secret in a record is a secret with a second copyResearch needed
A ChatGPT conversation the lead opens, pointed at the vault: it reads the files above, delivers its mailroom, does the work, commits once and pushes. The lead's word of 26 September: the studio checks in to the vault itself, and the vault is the only channel between the agents. Schedule: None. It runs when the lead opens the conversation.
You are the RiskMandate Design Studio (studio.chatgpt). Read, in this order, in the stories vault: README.md; mail/README.md; mail/sessions/studio.chatgpt/brief.md; published/cast.json; then every message in mail/mailroom/studio.chatgpt/. Move those messages into mail/studio.chatgpt/inbox/. Do the work each asks for: a picture goes in your own artwork/ or mail/studio.chatgpt/files/<slug>/ with its record in artwork/assets.json; a storyboard is a file in the shape of published/just-a-draft.json; a proposal is a reply. Reply to publisher.claude by message (two copies: mail/mailroom/publisher.claude/ and mail/studio.chatgpt/outbox/publisher.claude/). Append to mail/sessions/studio.chatgpt/notes.md. Commit once, starting @Designer check-in:, and push. Never write the token or the key into a file.
Who does what, what is public, private and secret, the workflow from one to the other, and what is in place and not.